Glossary of KVKK Terms
Short, clear definitions of the terms commonly used in personal data protection.
Personal Data
Any information relating to an identified or identifiable natural person — including name, national ID, email, phone, location and IP address.
Special-Category Personal Data
Sensitive data such as race, ethnicity, health, religion, sexual life, biometric and genetic data. Subject to stricter conditions and extra safeguards.
Data Controller
The natural or legal person who determines the purposes and means of processing and is responsible for the data registry system.
Data Processor
A natural or legal person who processes personal data on behalf of the controller under its authority (e.g. cloud/service providers).
Data Subject
The natural person whose personal data is processed. KVKK rights belong to this person.
Processing
Any operation performed on personal data — from collection, recording and storage to transfer and destruction.
Explicit Consent
Consent that relates to a specific subject, is based on information and given by free will. Revocable; not every processing requires it.
Duty to Inform (Privacy Notice)
The controller's duty to inform the data subject — about its identity, purposes, transfers and rights — before processing. Distinct from explicit consent.
VERBİS
The Data Controllers Registry. The registration obligation depends on criteria like headcount, financial balance sheet and activity type.
Processing Inventory
A structured record showing which personal data is processed for which purpose and legal basis, with whom it's shared and for how long.
Retention & Destruction Policy
A policy defining retention periods and the rules for deleting, destroying or anonymizing data at the end of those periods.
Data Breach
Unauthorized access to, unlawful disclosure of, or loss of personal data. In certain cases it triggers notification to the Authority and data subjects.
Cross-Border Transfer
Transfer of personal data to parties abroad, subject to conditions such as adequacy decisions, appropriate safeguards or exceptions.
Anonymization
Rendering personal data unable to be linked to an identified or identifiable person, even when combined with other data.
Authority / Board (KVKK)
The Personal Data Protection Authority and its decision body, the Board; holds regulatory, audit and enforcement powers.
Contact Person
The person who handles communication with the Authority on behalf of a VERBİS-registered controller. Does not assume the controller's obligations.
GDPR
The EU General Data Protection Regulation. Shares similar principles with KVKK and may also cover organizations processing EU residents' data.
Law No. 6698 (KVKK)
The Personal Data Protection Law. Entered into force on 7 April 2016; sets the core principles and obligations of processing personal data.
General Principles (Art. 4)
Lawfulness and fairness; accuracy and being up to date; specific, explicit and legitimate purposes; relevance, limitation and proportionality; retention only as long as necessary.
Lawful Basis (Processing Condition)
Grounds other than explicit consent that make processing lawful (Art. 5/6): provided by law, performance of a contract, legal obligation, made public, establishment of a right, legitimate interest, etc.
Legitimate Interest
A processing condition the controller may rely on, provided it does not harm the data subject's fundamental rights and freedoms.
Data Minimization
The principle that personal data be relevant, limited and proportionate to the purposes of processing; not collecting more than needed.
Purpose Limitation
Processing data only for specific, explicit and legitimate purposes, and not later using it in incompatible ways.
Accountability
The controller's ability to document and prove, in an audit, that it has met its compliance obligations.
Deletion
Rendering personal data inaccessible and unusable in any way for relevant users.
Destruction
Rendering personal data inaccessible, irretrievable and unusable by anyone (e.g. destroying physical media).
Periodic Disposal
Deleting, destroying or anonymizing expired personal data at recurring intervals (no more than every 6 months).
Masking
Hiding certain fields of personal data to make linking to a person harder. Unlike anonymization, it is often reversible.
Data Subject Rights (Art. 11)
Rights to request information, access, correction, erasure, learning the parties data was transferred to, objecting to automated processing, and compensation for damages.
Data Subject Request
The data subject's application to the controller to exercise their rights; requests are concluded within 30 days at the latest.
Administrative Measures
Organizational data-security measures such as policies, contracts, authorization, training and awareness (KVKK Art. 12).
Technical Measures
Technological data-security measures such as encryption, access control, logging, backups and penetration testing (KVKK Art. 12).
Encryption
Making data unreadable against unauthorized access; one of the core components of technical measures.
Logging (Audit Trail)
Recording system and access events in a traceable way so they can be reviewed afterwards.
Adequacy Decision
A Board decision permitting cross-border transfer by determining that a country or sector provides adequate protection.
Standard Contract
A contract notified to the Board that binds cross-border transfer to appropriate safeguards when there is no adequacy decision.
Binding Corporate Rules (BCR)
Approved, binding data-protection rules for cross-border transfers within a multinational group of companies.
Cookie
Small data files websites place on a user's device. Explicit consent is required for non-essential cookies.
Cookie Consent
Explicit consent obtained from the user before running non-essential cookies (aligned with KVKK 2026/347).
Profiling
Evaluating or predicting a person's interests, behavior or characteristics through automated processing of personal data.
Automated Decision-Making
A decision based solely on automated processing, without human intervention, that affects the data subject.
Right to be Forgotten
The data subject's ability, under certain conditions, to request erasure of their data or removal from search results.
Recipient / Recipient Group
The natural or legal person, or groups thereof, to whom personal data is transferred.
Third Party
A party other than the data controller, the data processor and the data subject.
Data Category
Groupings of personal data types such as identity, contact, personnel, finance and health.
Data Registry System
A recording system in which personal data is processed by being structured according to certain criteria.
Administrative Fine
An administrative sanction applied for breaches of obligations under KVKK Art. 18, updated each year by the revaluation rate.
Principle Decision
A general, binding decision issued by the Board to apply to all situations of a similar nature.
Board Decision Summary
A publicly shared summary of decisions the Board issues on specific complaints or notices.
Biometric Data
Special-category data that uniquely identifies a person based on physical/physiological traits such as fingerprint, face or iris.
Genetic Data
Special-category data relating to a person's inherited characteristics, whose processing is subject to special conditions.
Data Protection Impact Assessment (DPIA)
Assessing the privacy impact of high-risk processing in advance. Mandatory under GDPR; recommended as good practice under KVKK.
This content is for general information only; it does not constitute legal advice.

